Our Data

What NVZS collects, how we collect it, and what we never do with it.

What We Collect

When you look up a domain, NVZS fetches and stores the following data points about that domain — not about you:

SSL Certificate
Certificate type, issuer, validity dates.
Domain Registration
Registration date and calculated age from public WHOIS data.
Server Location
Country/region of the hosting server resolved from the IP.
Server & Tech
Server software (nginx, Apache…) and detected CMS/frameworks.
Security Headers
Presence or absence of HTTP security headers (CSP, HSTS, etc.).
Email Security
DMARC record, MTA-STS policy, SMTP TLS reporting.
Security.txt
Whether the domain publishes a responsible-disclosure policy.
Sitemap
URL of the domain's sitemap.xml and number of indexed pages.
Domain Extensions
Availability of related TLDs (.com, .net, .org, etc.).
Open Graph Tags
Social share title, description, and image meta tags.
NVZ Score
Calculated 0–100 score based on the above metrics.
How We Collect It

All data is collected by our servers at scan time using publicly available, passive techniques:

  • HTTP/S requests — we fetch the domain's homepage and inspect headers and HTML, exactly as a browser would.
  • DNS queries — we look up MX, TXT (DMARC, MTA-STS), and CAA records using standard DNS resolution.
  • WHOIS / registration data — we query public WHOIS APIs for registration date. We do not store personal registrant contact data.
  • IP geolocation — we resolve the domain's A record and map the IP to a country using a third-party geolocation database.
  • No crawling — we do not spider a domain's internal pages. We only look at the root URL, a small set of well-known paths (/robots.txt, /sitemap.xml, /.well-known/security.txt), and DNS records.
Data Freshness & History

Each scan result is stored in our database and timestamped. If a domain has been scanned before, the previous result is moved to an archive so you can see how a domain's security posture has changed over time.

You can request a fresh scan at any time using the Re-Scan Now button on any results page. Cached results are never served to users without a visible timestamp indicating when they were last scanned.

What We Never Do
  • We never sell domain data or scan results to third parties.
  • We never store personal registrant contact data from WHOIS (names, addresses, phone numbers).
  • We never log the IP addresses of visitors who perform lookups.
  • We never attempt to exploit or actively probe domains — all collection is passive and read-only.
  • We never share individual scan results with any domain's owner or any advertiser.
NVZ Score Methodology

The NVZ Score is a 0–100 composite score calculated from the metrics above. Points are awarded for good security practices and deducted for missing ones. See the NVZ Score page for a full breakdown.

85 – 100
Outstanding
Exemplary security posture across all metrics.
70 – 84
Good
Strong fundamentals with minor gaps.
50 – 69
Fair
Some key security practices are missing.
0 – 49
Poor
Significant vulnerabilities or missing protections.
Data Removal Requests

If you own a domain and would like its scan history removed from NVZS, please contact us with the domain name and verification that you control it. We will remove all stored data within 7 business days.